SB2025041033 - Improper Verification of Source of a Communication Channel in FortiClientEMS
Published: April 10, 2025 Updated: May 20, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Verification of Source of a Communication Channel (CVE-ID: CVE-2024-36506)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper verification of source of a communication channel in administrative interface. A remote attacker can bypass the trusted host feature via session connection.
Remediation
Install update from vendor's website.